[sldev] Security Update 2008-10-06 to SL Viewers and source code - CLARIFICATION

Ambrosia chaosstar at gmail.com
Tue Oct 7 00:50:43 PDT 2008


Um, Gordon.

Rob said 3rd party viewer creators can contact him and ask for the
source code in advance.

Which will be released to the public tomorrow, so either way tomorrow
3rd party coders can patch the fix into the most ancient viewers there
are.

While I understand the frustration about no immediate availability of
the fix, this hardly makes any work 'worthless', and what you get is a
24 hour delay -if your request does not get approved-.

Seriously, take a breather here. it's not like they're doing the delay
just to laugh at your face. They're doing it so the majority of SL
users is potentially protected before the source (and thus an exact
way to put together attack code) gets released. And, as he said, if
you maintain a 3rd party viewer, you can apply to get it earlier.

On Tue, Oct 7, 2008 at 07:15, Gordon Wendt <GordonWendt at gmail.com> wrote:
> So this is essentially a huge fuck you to all the third party viewer makers
> and users since while I'd guess the vast majority of third party viewers are
> using the old code solely for the old UI and graphics if nothing else you
> have essentially told them don't bother because with one or two days notice
> all your work is worthless and we're going to push this out on you whether
> you like it or not.  I won't be surprised and won't hold any blame against
> them if some of the third party viewer makers give up if your going to treat
> them like this.  This is unacceptable behavior from LL and further proof of
> an unacceptable attitude towards it's customer base.  Some of you are going
> to ask who am I to say this? I am a loyal user of SL, I have overall been a
> defender of SL and LL time and time again but LL still does stupid stuff
> like this over and over again to it's customers.
>
> Rob, Since you want this list to be constructive I will give some
> constructive suggestions.  Listen to the third party client designers, they
> say they hate windlight or new UI changes ok fine roll out the changes but
> don't screw them over.  I realize it takes extra work to make multiple
> patches for multiple versions so pick maybe two or at most three versions,
> the release and two backdated.  Give the release your full attention however
> when it comes to huge fixes like this that can't be optional put in the
> extra work and make a compatible patch for the latest 1.9 series viewer.  I
> guarantee that the extra work will pay itself back in the goodwill you will
> get not only from the creators of third party viewers but from the users who
> use them as well.  I believe it would be impossible for to get solid numbers
> on how many people use third party vs the main viewer (although LL may very
> well have them) however I strongly believe that they are numerous and grow
> each time LL decides to turn their UI a different color.  My immediate
> suggestion would be to roll this out on time however at the same time give a
> short timeframe until when you'll have a patch out for the 1.9 series and
> stick to that timeline.  Because of the extra testing involved I understand
> that it would take awhile but with the promise of a compatible patch I'm
> sure that many people would be willing to wait and use the LL viewer
> temporarily until it came out even if that was a month from now.  Otherwise
> you face killing your open source initiative by crapping on third party
> designers and users one too many times.
>
>
> Note: My language comes out as being unsophisticated and harsh in the above
> and probably breaks a few rules however despite my intentions to go over and
> edit the swears out however after finishing it I have realized that it would
> take away the honesty I am attempting to convey here and if that gets be
> modbitted so be it if it makes a difference... and that's not just trying to
> be dramatic if it makes a difference it really is worth whatever fate Rob
> has in store for people who curse on the mailing list.
>
> _______________________________________________
> Policies and (un)subscribe information available here:
> http://wiki.secondlife.com/wiki/SLDev
> Please read the policies before posting to keep unmoderated posting
> privileges
>


More information about the SLDev mailing list